What is the best way to log DNSSEC failures in Bind without enforcing DNSSEC validation? That is I want to see what Bind would have rejected because of failed DNSSEC validation, but I do not want to return SERVFAIL to my client. -- Augie Schwer - Augie at Schwer.us - http://schwer.us